On 17 September 2026, the Commodity Futures Trading Commission's Market Participants Division published a no-action position that will quietly reshape what the app next to your hardware wallet is allowed to offer you. Under Release 9300-26, staff said they won't recommend enforcement against providers of what the letter calls passive software for failing to register as introducing brokers, so long as the software's job is limited to connecting its users to firms that are already registered. Non-custodial trading now has a defined regulatory lane in the United States, and the condition that opens it is the thing self-custody holders care about most.
What the letter covers
The relief is narrow by design. A passive software provider, in the division's framing, builds and distributes a front-end interface that lets people reach regulated derivatives markets without the software exercising discretion over how orders are routed or executed, generating trading signals, or taking control of anyone's assets. Where that description holds, the provider and its personnel escape registration as an introducing broker or an associated person of one.
Escaping registration is not the same as escaping obligations. Staff Letter 26-25 attaches ten conditions, and they read like a compressed version of the duties a registered firm carries anyway: disclosures and risk warnings delivered to users, written agreements with the registered entities on the other side, personnel standards, user verification, records kept and available, notification if the provider becomes insolvent, and submission to the CFTC's jurisdiction. A provider that drifts outside any of those conditions is outside the relief.
This also isn't the first letter of its kind. The division granted the same treatment to a single company, Phantom Technologies, in Release 9197-26 on 17 March 2026 under Staff Letter 26-09. What changed in September is that the framework stopped being a one-off permission and became something other similarly situated providers can rely on without asking first.
Why non-custodial trading is the hinge
Read the conditions in order and a pattern emerges. The relief turns on the software not holding your assets and not deciding anything on your behalf, which means a regulator has drawn its line in the same place self-custody advocates have been drawing it for years. Custody is what creates the risk that registration exists to manage, so software that never takes custody gets treated as what it is: a window onto somebody else's regulated venue.
That's a useful piece of vocabulary to have, because "non-custodial" tends to get used loosely in marketing. Here it carries a specific test with consequences attached. The provider cannot hold your coins, cannot route at its own discretion, and cannot pick your trades. Anything more hands-on and the lighter treatment evaporates.
What it changes for you
Expect the wallet apps you already use to start offering futures and event contracts inside the interface, because the regulatory cost of doing so just dropped. That convenience is worth having, and it comes with a distinction that's easy to lose in a clean piece of product design.
Your wallet holding your keys and your position being held somewhere else are separate facts that can both be true on the same screen. Margin posted against a derivatives position sits with the registered firm on the other side for as long as the position is open, which means those funds have left self-custody whatever the app around them is called. The software is non-custodial; the trade is not. If a venue or an intermediary fails while your collateral is with it, you're a creditor in the ordinary way, and the CFTC's letter does nothing to change that because it was never trying to.
So the question to carry into these features is which pool of money you're using. Coins you're willing to trade and coins you intend to hold for a decade have different requirements, and one wallet interface offering both makes the boundary between them a decision rather than a default.
What to check before you approve anything
Any new trading surface inside a wallet app means new transactions to sign and new contract permissions to grant, and the app is the part of the stack most exposed to tampering. A hardware wallet helps here for a specific reason: the request is composed on the phone and confirmed on the device, so what you're agreeing to appears on a screen the software cannot rewrite.
On Ryder One every transaction is shown in readable detail on the 1.6-inch AMOLED touchscreen before you approve it, the private key is generated inside an EAL6+ certified Infineon SLC38 and never leaves the chip, and the physical button that authorises a signature is wired directly to the secure element so no software path can sign without it. Communication is NFC only, which keeps the device unreachable except while you're holding it against the phone.
Separating the trading stack from the long-term backup
The practical answer to a wallet that now does more things is keeping the holdings you never intend to trade behind keys that never meet a trading interface. That's an ordinary habit rather than paranoia, and it makes the backup question the one that matters most, because the coins you're protecting are the ones you plan to still own long after any given app has changed shape.
A written seed phrase on paper avoids every online exposure and then has to survive damp, fire and a decade of house moves. Stamping the words into steel handles those hazards and leaves your entire position resting on one object nobody finds, which improves the odds without altering the structure of the risk. TapSafe Recovery was designed to remove that single point of failure: half of what a restore needs sits on the Recovery Tag and half travels with your paired phone, held encrypted in your own iCloud or Google Drive rather than on the handset. Neither half on its own gives up anything usable, and the two together restore the wallet. Recovery Contacts are optional, each hold a quarter share, and can see no balances or addresses at any stage. The words themselves stay available on the device as a last resort under the BIP-39 standard, so moving to other hardware is always open to you.
Where that leaves things
A regulator has now written down, twice in six months, that software which doesn't hold your assets deserves lighter treatment than software that does. That's a good outcome for self-custody and a clear signal about where the line sits. It also means more places inside familiar apps where you'll be asked to approve something, which puts more weight on being able to read a request on hardware you control before it becomes a signature.
Ryder One is 149 USD for the Starter Combo and 179 USD for the Super Safe Combo, with a Recovery Tag, wireless charger and pouch in the box. The firmware has been audited by Halborn, with the full report public, and setup runs about 60 seconds across three NFC taps.




Share: